Page 1 of 1

+Button4

Posted: Wed Aug 13, 2008 11:49 pm
by LilleBror
http://register.eswc-usa.com/files/eswc ... les_q3.pdf

Cant we get the expliot cmd removed, its in ET.

Plus a cleanout of all the overlay bogus cmds that can be sent.

/fu
/+salute
/+attack2
ect..

Posted: Thu Aug 14, 2008 7:39 am
by MeeZ
+button4 could be denied with lua files, at least as a solution for leagues?

what exactly does it do?

Posted: Thu Aug 14, 2008 8:56 am
by LilleBror
Ask the guru's

what i have found out...

"state of inactivity like when you pull down the console"

//exploit
bind d +vstr d1 d2
seta d1 "+button4 ; +moveright ; -button4 ; -button4"
seta d1 "+button4 ; -moveright ; -button4 ; -button4"
//repeat all action keys

so basicly what will happen is "graphic lagg" when others try to track you.

worst part is that its old school quake...

so the remarkable thing is why the junk cmd's have not been disabled?
but again ask the guru's

ill say one thing we have screenshots.. why on earth is there not a possiblity to get raw cmd's printed out, and cvars and binds.
screenshot's what is he seeing.
datashot's what is he sending.
configshot's what cvars settings he is using.
bindshot's what binds he is using.

as an ex server admin i would have like this..
take a datashot find out that someone is junking the server... and issu a kick. "only the cmd's from the menu please"
take a configshot and find "homemade" cvars and kick.. "i dont know all your cvars ur gone"
take a bindshot +vstr multi action keys... and kick "get skill nabiee"
take a bindshot +vstr multi action keys with cvar change... and kick "lol leet bye bye we prefer players with hitable hitboxes"

Posted: Thu Aug 14, 2008 12:42 pm
by ReyalP
Dear lillBror

You have an excellent imagination.

@Meez:
You can't affect buttons via lua.

Posted: Thu Aug 14, 2008 12:50 pm
by Fusen
I fully agree with everything lillebrou has said, including the worst offender of them all

cg_placebo!

ATOP THIS ABOMINATION
________
Toyota TownAce history

Posted: Thu Aug 14, 2008 2:39 pm
by LilleBror
imagination?
from 3.03
- Pmoved_fixed must remain at default (0)
- button4 may not be triggered

or the rest of the rant...?

being honest here when i found out that "lagg" can be generated stuffing the server from the client with bogus cmd's i was very disapointed.

that haxx claim they can filter it.. is even more disturbing since its a copy paste job for the developers... assuming the the mod team gather know public haxx...

on the money side... when hosting a server i pay 4 bandwith use... so basicly id would like a tool so only the cmd's from the menu are sent.. and its keystokes with fingers only.... and mouse cordinates...ofc...
and if anyone think its cool to change cvars rapidly thats cpu load and that means that i a a server owner am "forced" to rent a massive CPU machine with lots of ram..to try to minimize lagg = cost more than the game spec's justify...

the suckage is that the demo and game experiance differ alot..
why? hmm if sever admins can get the "data" they can be the judge of what is accepted and what is not. Plus anything "used" is public knowhow within days...

its funny that clan match's only require a demo... it should be the full readout of bind's cvar settings and cmd history logg'ed...

but again where is the full documentation on all cvars and cmd's?

// generated by ET, do not modify
o'well since we are past this, I personly as a (ex)admin would more control over what i would permit...

again... boomtown #1 server was 44+ acc average... 1 value cvar setup style...

the only problem may i stress was "aimbot" cheat heaven experiance some players got... yes 3 set of eyes and gunz will kill u so fast that u go holy XXXX (triple HS from 3 players at the same time)

im thinking about opening a new server with FUD bindkicker with ; +vstr and exec restictions plus all the cmd's that are not in the menu option's +strafe,+attack2 +button1 +button4 +salute +useitem ect... and ofc the full monty on all com_ cl_ and physics cvars

but ill imagin it 4 now...

Posted: Mon Aug 18, 2008 2:37 am
by Luk4ward
ReyalP wrote: @Meez:
You can't affect buttons via lua.
Why is that? Will it be updated in next etpro or smth?

Posted: Mon Aug 18, 2008 11:36 am
by gotenks
@meez
+button4 must be a command, i think you're thinking of mouse3 etc... that's different...

Posted: Mon Aug 18, 2008 12:39 pm
by LilleBror
Luk4ward_>

you are asking the wrong question...

you should ask imho...
Why can the client send anything that is not is not configurable in the menu section?

workaround.. FUD bind kicker... kick'em if they dont behave nice...

Posted: Tue Aug 26, 2008 7:37 am
by mortis
seta g_placebo 1

Re: +Button4

Posted: Sun Nov 01, 2009 2:48 am
by locki
LilleBror wrote: /+salute
We just need this mapped to play the nazi_salute animation. Go on... you know you want to :D (can LUA trigger a client's model to play a specific animation?)

Posted: Sun Nov 01, 2009 8:36 am
by gotenks
lua would not beable to do that

Posted: Thu Nov 05, 2009 4:54 am
by locki
QMM is the answer.

=FF=im2good4u ?